CVE-2026-39571 PUBLISHED

WordPress Instantio plugin <= 3.3.30 - Sensitive Data Exposure vulnerability

Assigner: Patchstack
Reserved: 07.04.2026 Published: 08.04.2026 Updated: 08.04.2026

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Themefic Instantio instantio allows Retrieve Embedded Sensitive Data.This issue affects Instantio: from n/a through <= 3.3.30.

Product Status

Vendor Themefic
Product Instantio
Versions Default: unaffected
  • affected from 0 to 3.3.30 (incl.)

Credits

  • Que Thanh Tuan | Patchstack Bug Bounty Program finder

References

Problem Types

  • Exposure of Sensitive System Information to an Unauthorized Control Sphere CWE

Impacts

  • Retrieve Embedded Sensitive Data